Advanced Forensic Audit Investigation and Interviewing Training Course

5 days Auditing Certificate on completion
Course codeSD-A-053
Duration5 days
LevelIntermediate
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, anomaly, or whistleblower report into a defensible work plan; preserve evidence without contaminating it; analyse transactions at scale; and conduct interviews that obtain reliable information without making unsupported accusations. This course addresses the point at which internal audit, finance, compliance, and investigation teams need to move from identifying red flags to building a fact-based case that can withstand executive, legal, regulatory, or disciplinary scrutiny.

Over five days, participants apply a structured forensic audit methodology from case intake through reporting. They learn to define allegations and investigative hypotheses, assess fraud risks under ISA 240, establish evidence chains of custody, design targeted data tests, use Excel and IDEA for anomaly detection, review documents and digital records, and distinguish corroborated facts from inference. The interviewing modules cover witness preparation, PEACE-based questioning, cognitive interviewing techniques, deception indicators used cautiously, admission-seeking boundaries, and contemporaneous interview documentation.

Instruction combines expert-led briefings with a multi-stage financial misconduct case. Participants work with transaction extracts, emails, invoices, approval records, and interview scenarios to develop an investigation plan, evidence register, data-testing rationale, interview plan, and concise forensic findings report. They leave with a reusable investigation case-file pack and an individual action plan for applying the methods within their organisation. A certificate is awarded on completion.

The course is designed for experienced audit and assurance professionals who already understand financial controls and need stronger investigative, analytical, and interviewing capability for complex or sensitive matters.

Course objectives

By the end of this course, participants will be able to:

  • Formulate allegation statements, investigation objectives, and testable fraud hypotheses for a forensic audit case
  • Apply ISA 240 fraud-risk principles to prioritise investigative scope, evidence sources, and control-override testing
  • Construct an evidence register and chain-of-custody record that preserves source integrity and auditability
  • Perform targeted transaction tests in Excel and IDEA to identify duplicates, outliers, split payments, and unusual vendor activity
  • Develop a document-review protocol that links invoices, approvals, communications, and financial records to case hypotheses
  • Prepare a PEACE-based interview plan with issue sequencing, open questions, exhibits, and corroboration objectives
  • Conduct structured fact-finding interviews using active listening, probing, challenge, and contemporaneous note-taking methods
  • Produce a defensible forensic findings report that separates facts, analysis, limitations, and recommended actions

Benefits of attending

For you

  • Gain a repeatable method for leading investigations from allegation intake through final findings
  • Build confidence conducting difficult witness and subject interviews without relying on accusatory questioning
  • Strengthen credibility with legal, compliance, and executive stakeholders through defensible evidence handling
  • Create stronger audit committee reports by separating verified facts, analytical conclusions, and unresolved limitations
  • Expand eligibility for forensic audit, investigations, ethics, and financial-crime assignments

For your organisation

  • Reduce the risk of poorly scoped investigations that waste time or miss critical evidence
  • Improve preservation and documentation of evidence for disciplinary, legal, or regulatory review
  • Detect suspicious payment, vendor, and journal-entry patterns earlier through targeted data testing
  • Create more consistent interview practices across audit, compliance, HR, and finance investigations
  • Convert investigation findings into specific control remediation priorities and accountable action plans

Target competencies

Forensic audit planningEvidence chain custodyFraud data analyticsInvestigative interviewingDocumentary evidence reviewForensic report writing

Who should attend

  • Internal Audit Managers — who lead sensitive reviews and need investigations that withstand audit committee scrutiny
  • Forensic Auditors — who require stronger evidence, analytics, and interviewing methods for complex cases
  • Financial Controllers — who investigate irregular transactions, control overrides, and suspected financial misconduct
  • Compliance and Ethics Officers — who manage whistleblower allegations and coordinate fact-finding responses
  • Risk Managers — who need to assess fraud exposure and convert investigation findings into control improvements
  • External Audit Seniors and Managers — who encounter fraud indicators and need disciplined escalation and evidence techniques

Requirements and prerequisites

Participants should have practical experience in internal audit, external audit, financial control, compliance, or fraud-risk work. They should understand financial statements, transaction cycles, segregation of duties, audit evidence, materiality, and basic audit sampling. Familiarity with Excel formulas, filters, PivotTables, and reviewing invoices or general-ledger extracts is assumed; the course builds from these skills into forensic analysis. Prior experience of conducting investigations or interviews is helpful but not required. Participants do not need legal qualifications, coding skills, prior use of IDEA or Relativity, or specialist digital-forensics experience.

Training methodology

The programme uses instructor-led forensic audit demonstrations, guided data-analysis labs, document-review workshops, and coached interview practice. A running case involving suspected procurement fraud and management override develops across the five days. Participants analyse general-ledger and vendor data in Excel and IDEA, build an evidence register, review simulated communications and approvals, and conduct role-play interviews with observers using structured feedback sheets. Small groups present their findings to a mock investigation steering group, then complete an individual workplace application plan.

Course outline

Day 1: Forensic audit strategy and case control

  • Forensic audit versus routine assurance engagement objectives
  • Allegation framing and investigation issue trees
  • Fraud triangle, fraud diamond, and behavioural red flags
  • ISA 240 responsibilities and management override considerations
  • Scoping decisions, materiality, and investigative proportionality
  • Investigation governance, independence, and conflict-of-interest controls
  • Case plans, milestones, decision logs, and escalation protocols

Workshop: Participants convert a whistleblower allegation into a scoped investigation charter, hypothesis matrix, and initial evidence-source map.

Day 2: Evidence preservation and financial data analysis

  • Evidence relevance, reliability, authenticity, and admissibility considerations
  • Chain-of-custody forms and evidence register design
  • General-ledger extraction and data-quality validation procedures
  • Excel PivotTables, XLOOKUP, conditional formatting, and duplicate testing
  • IDEA functions for gap detection, stratification, and Benford analysis
  • Journal-entry testing for override, round amounts, and unusual posting times
  • Vendor, payment, and purchase-order anomaly tests

Workshop: Participants analyse a simulated accounts-payable and general-ledger extract to produce a ranked suspicious-transaction schedule with test rationale.

Day 3: Documentary and digital evidence review

  • Document-review protocols and coding frameworks
  • Invoice, contract, approval, and receiving-record triangulation
  • Email chronology construction and communication pattern analysis
  • Metadata awareness and preservation boundaries for non-specialists
  • Relativity review workflows, tags, searches, and issue coding
  • Corroboration matrices linking evidence to investigative hypotheses
  • Handling exculpatory evidence and alternative explanations

Workshop: Participants review a case document set and create a chronology, corroboration matrix, and list of evidential gaps requiring follow-up.

Day 4: Forensic interviewing and statement assessment

  • Interview objectives, sequencing, and witness prioritisation
  • PEACE model phases for investigative interviews
  • Cognitive interviewing techniques for recall and detail
  • Open, probing, clarifying, and challenge-question design
  • Rapport, silence, active listening, and neutral language
  • Exhibit presentation and testing statements against evidence
  • Contemporaneous notes, interview summaries, and statement validation

Workshop: Participants conduct and observe a role-play witness interview, producing an interview plan, question log, and evidence-linked interview summary.

Day 5: Findings, reporting, and remediation

  • Assessing sufficiency of evidence and investigative limitations
  • Fact, inference, opinion, and allegation distinctions in reporting
  • Forensic report structure for executives, legal counsel, and audit committees
  • Quantifying financial exposure, loss, and recovery considerations
  • Root-cause analysis of control failure and management override
  • Remediation recommendations, ownership, and verification measures
  • Investigation closure, record retention, and lessons-learned reviews

Workshop: Participants present a forensic findings report and remediation plan to a mock steering committee, receiving instructor feedback on evidential logic and report clarity.

Tools & standards covered

Microsoft Excel, IDEA Data Analysis, Relativity, ISA 240

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should already understand audit evidence, internal controls, financial transaction cycles, and basic Excel analysis. The course is not an introduction to auditing; it develops intermediate audit experience into structured forensic investigation capability.

A laptop is recommended for live online delivery and useful for classroom data exercises where permitted by the provider. No prior IDEA or Relativity experience is required; guided exercises introduce the relevant workflows and functions.

It is best suited to internal auditors, forensic auditors, financial controllers, compliance officers, risk managers, and experienced external auditors. Participants should be likely to handle suspected fraud, misconduct, control override, or whistleblower allegations.

General fraud courses focus on recognising red flags and control risks. This course concentrates on the operational work after concerns arise: scoping an investigation, preserving evidence, analysing records, conducting interviews, and writing defensible findings.

Participants can adapt the investigation charter, evidence register, hypothesis matrix, data-test schedule, interview plan, and report structure for live or future cases. The methods also improve how teams document sensitive audit exceptions before escalation.

You leave with a completed forensic case-file pack containing your investigation plan, evidence register, analytics outputs, document chronology, interview materials, and findings report. You also receive an individual action plan for embedding the approach in your organisation.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

COBIT 2019 Control Assessment for IT Auditors Training Course

IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and p…

5 Days Certificate

ISACA ITAF Audit Framework Application Training Course

Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior managem…

5 Days Certificate

Grant Compliance Auditing for NGO Finance Teams Training Course

NGO finance teams must demonstrate that restricted funds were spent for the approved purpose, charged to the correct grant, supported by rel…

5 Days Certificate

SAP Audit Management Reporting and Workflow Training Course

Internal audit teams need timely, defensible reporting without relying on disconnected spreadsheets, email-based review cycles, or manual st…